Mirage2FA Phishing Campaign Targets Microsoft 365 Sessions
A new phishing operation is showing why MFA alone cannot stop every modern account takeover. Security researchers have identified Mirage2FA, a Phishing-as-a-Service platform designed to steal authenticated Microsoft 365 sessions. [...]
Citrix NetScaler Flaw Allows Unauthorized Access
Cloud Software Group has warned customers about two serious security vulnerabilities affecting NetScaler ADC and NetScaler Gateway, previously known as Citrix ADC and Citrix Gateway. The vulnerabilities, tracked as CVE-2026-19489 [...]
Hackers Target Critical MLflow SSRF
A critical security flaw in MLflow is being targeted by attackers, putting internet-facing machine learning infrastructure at risk. MLflow is widely used by data science and machine learning teams to [...]
Malicious Google Scripts Deliver Windows Malware
A sophisticated cryptocurrency-focused campaign is abusing trusted Google services as part of a multi-stage attack designed to identify valuable targets and deliver Windows malware. The operation begins with what appears [...]
Massive DDoS Attack Hits Threema
Privacy-focused messaging platform Threema recently experienced a series of large-scale distributed denial-of-service (DDoS) attacks that temporarily affected service availability. The disruption began on Tuesday evening and continued intermittently into Wednesday [...]